Introduction
EJBCA Concepts
EJBCA Architecture
Using EJBCA as a Standalone CA/RA/VA
EJBCA with distributed RA/VAs
High Availability and Clustering
External OCSP Responders
Maximizing Performance
Internal Architecture
Library Manifest
Interoperability and Certifications
Supported Hardware Security Modules (HSMs)
Supported Algorithms
Common Criteria
Common Criteria Evaluation
Installation
Installation Prerequisites
Managing EJBCA Configurations
How to Configure Database Protection using HMAC
Creating the Database
Application Servers
WildFly 38
WildFly 35
WildFly 32
JBoss EAP 8.0
Deploying EJBCA
Installing EJBCA
Install EJBCA as a CA with a Management CA
Install EJBCA as a CA without a Management CA
Install EJBCA as an RA or VA
Finalizing the Installation
Deployment Reference
Upgrading EJBCA
Operations
EJBCA CA Concept Guide
End Entities Overview
End Entity Profiles Overview
E-mail Notifications
End Entity Profiles Fields
Certificate Statuses
Subject Distinguished Names
Custom Subject DN and altName OIDs
Publishers Overview
Active Directory Publisher
Custom Publishers
Publishing with an External Application
Certificate Sampler Custom Publisher
Cert Safe Publisher for an HTTPS Server
Cert Safe REST API
Customer Specific Publisher for a PKD-like Catalog
LDAP Publisher/LDAP Search Publisher
Multi Group Publisher
Validation Authority Peer Publisher
Validation Authority Publisher (Legacy)
SCP Publisher
AWS S3 Publisher
Azure Blob Storage Publisher
Certificate Profiles Overview
Certificate Transparency Overview
Custom Certificate Extensions
Extended Key Usages
External Account Bindings
Certificate Profile Fields
Approvals
Approval Profiles
Accumulative Approval Profiles
Partitioned Approval Profiles
Services
Certificate Expiration Check Service
CRL Download and CRL Update Service
HSM Keepalive Service
Publisher Queue Process Service
Rollover Service
User Password Expire Service
Certificate and CRL Reader Service
Remote Internal Key Binding Updater
Database Maintenance Service
Pre-Certificate Maintenance Service
OCSP Response Pre-Signer
CRL Updater Service
Renew CA Service
Microsoft Intune Certificate Revocation
OAuth Key Update Worker
Remote Authenticators Overview
Roles and Access Rules
Access Rules
Predefined Role Templates
Protocols
Certificate Store Access via HTTP
OCSP
OCSP Response Extensions
Archive Cutoff
CertificateHash
Unid FNR
Web Service Interface
EST
EST Client Mode Configuration
EST RA Mode Configuration
EST over CoAP
ACME
ACME with acme.sh
ACME with Certbot
ACME with acme4j
ACME Device Attestation
CMP
CMP Interoperability
CMP Error Messages
Using CMP with 3GPP
EJBCA REST Interface
SCEP
Microsoft Auto-enrollment Overview
Character Limitations
Crypto Tokens Overview
Authentication Methods
OAuth Providers
Logging
Audit Log Overview
Integrity Protected Security Audit Log
Security Audit Events
Subject Name Log Redaction
Peer Systems
Validators Overview
Certificate Field Validators
CAA Validator
MPIC Validator
Post Processing Validators
pkimetal Validator
External Command Certificate Validator
Key Validators
OCSP Responders
EJBCA Security
Certificate Authority Overview
C-ITS ECA Overview
Chimera CA
Partitioned CRLs
EdDSA Keys and Signatures
ePassport PKI
ECDSA Keys and Signatures
CVC CA
CVC Sequence
EAC Roles and Access Rights
Inspection Systems
Using HSMs
PEM Requests
SPOC TLS Certificates
Post-Quantum Cryptography Keys and Signatures
SSH CA
CA Fields
Creating Custom Request Processors
Microsoft Compatible CA Key Updates
Audit Log Archival
EJBCA RA Concept Guide
EJBCA Operations Guide
CA Operations Guide
EJBCA Overview Page
Approving Actions
CRL Generation
Synchronizing the VA Database
EJBCA Maintenance
Monitoring and Healthcheck
Monitoring of VAs
Clearing System Caches
Backup and Restore
Web UI Sessions
End Entities
Issue a New Server Certificate from a CSR
SSL Certificate Expiration
Certificate Renewal
Create Server Certificates
Issue a New PKCS#12 Keystore for an SSL Server
Create User Certificates
Renaming and Editing Users
End Entity Profile Operations
Create an End Entity Profile for SSL Servers
Enrollment Protocol Configuration
CMP Operations Guide
CMP Client Support
3GPP CMP Operations
3GPP CMP Questions and Answers
Modular Protocol Configuration
Microsoft Auto-enrollment Operations
Microsoft Auto-enrollment Configuration Guide
Part 1: Configure Active Directory Domain Services
Part 2: Group Policies and Certificate Templates
Part 3a: EJBCA Configuration
Part 3b: EJBCA Policy Server Configuration
Enabling TLS for Active Directory Connection
Part 4: Configure Policy Server
Microsoft Auto-enrollment Troubleshooting
SCEP Operations Guide
SCEP Client Support
Exporting and Importing Profiles
Managing CAs
Creating an Issuing CA Signed by an External Root
Importing an External CA
Signing an External CA
CA Rekey Recommendations
Managing C-ITS ECAs
Creating a Chimera CA
Creating an Issuing CA Signed by a Root on Same Node
Creating a Root CA
Managing Certificate Profiles
Create a Certificate Profile for SSL Servers
Create a Certificate Profile for a Document Signer for Passports
Import/Export Certificate Profiles
Certificate Transparency
Managing Crypto Tokens
CP5 Crypto Token
Soft Migration from SunPKCS11 Crypto Token to P11NG Crypto Token
Managing Remote Authenticators
Setting up a Remote Authenticator
OAuth Provider Management
Configuring Audience Claims
Setting up OAuth Using Keycloak
Setting up OAuth Using Okta
Setting up OAuth Using Azure Active Directory
OCSP Responder Management
Setting up a Responder Using the CLI
OCSP Response Pre-Production
Peer Systems Operations
Adding an Outgoing Peer Connection
Roles and Access Rules Operations
Managing Role Namespaces
Managing CVC CAs
Creating a CVC CA
Creating a DV CA and Issuing Inspection System Certificates
Publishers Management
Publisher Queue
Setting up a Validation Authority Peer Publisher
Key Recovery
Key Import
Importing Certificates
RA Operations Guide
Connecting an RA to a CA over Peers
Certificate and End Entity Life Cycle Management
Creating Certificates on the RA
Self-Renewal of Soft Client Certificates
Managing Requests in the RA UI
Managing Roles and Access Rules from the RA
RA Administrator Access Rules
Configure EJBCA for Public Access
Customizing the RA Appearance
Command Line Interfaces
EJBCA Client Toolbox
P11Ng CLI
ConfigDump Tool
Integration
Integrating with Third-Party Applications
Access EJBCA using USB Tokens and Smart Cards
Using YubiKeys with EJBCA
Microsoft Intune Device Certificate Enrollment
Certificate Enrollment Requirements
Configure EJBCA Server
Configure Intune
Enroll Windows 10 Devices to Intune
Integrating EJBCA with Azure AD Role Based Authentication (RBAC)
Integrating EJBCA with Azure Application Insights
Subordinate HashiCorp Vault CA to EJBCA Root
Enrolling Chrome OS Devices against EJBCA
Integrating EJBCA with Graylog
Issuing Certificates to Kubernetes Services using cert-manager
Versasec Card Management System Integration
Ciphermail Email Gateway and EJBCA Integration
3Key Dashboarding, Monitoring and Reporting Add-on
EJBCA and Cisco ISE
EJBCA and Cisco IOS
Configure EJBCA with OpenSSO
Setting up an Apache Web Server as a Proxy
Add an EJBCA Sub CA to a Microsoft Standalone Root CA
Setting up an Apache Web Server with mod_jk
Using CertBot to Issue Certificates with ACME to an Apache Web Server
Setting up a HA Proxy in front of EJBCA
VMware Workspace ONE UEM powered by AirWatch
ServiceNow REST Integration
ServiceNow REST Integration - Configure EJBCA
ServiceNow REST Integration - Configure ServiceNow
3Key RA Profiles Add-on
Hardware Security Modules (HSM)
Generic PKCS#11 Provider
AWS CloudHSM
AWS KMS
Azure Key Vault and Managed HSM
Bull TrustWay Proteccio
Bull Trustway PCI Crypto Card
Crypto4A QxHSM
Fortanix Data Security Manager
Google KMS
IBM HPCS
nCipher nShield/netHSM
Nitrokey HSM
Securosys Primus HSM and CloudHSM Service
SmartCard-HSM
SoftHSM
Thales DPoD
Thales Luna HSM
Thales ProtectServer
Trident HSM
Utimaco CryptoServer
Utimaco CryptoServer CP5
Thales TCT Luna SA
Utimaco uTrust
YubiHSM 2
EJBCA Guides
Quick Start Guide - Start EJBCA Container with Client Certificate Authenticated Access
Enabling Debug Logging
Issue Composite Certificates
Configure EJBCA ACME Device Attestation with Jamf for Apple devices
Create CAs for Matter IoT
Create CAs for Matter Vendor PKI
Create CAs for Matter Operational PKI
Migrating from other CAs to EJBCA
Migrating RSA Keon CA with nCipher
Migrating an OpenSSL CA to EJBCA
Migrating Verizon using nShield HSM to EJBCA
Migrating Microsoft CA to EJBCA
Modifying EJBCA
Getting Started With EJBCA Development
Handling Configurations in a Separate Directory
Customizing the User Interface
Adding Rules to Regulate Values of End Entity Fields
Creating a Custom RA application using EJBCA Web Services and Java
Allowing Custom Classes in the Database
Creating Plugins
RA Chaining Architecture for Multi-Tenant Environments
Specialized CA Workflows
Change Signing Algorithm on Root CA's Certificates
Issue Multiple Certificates at Once Using a Bulk of CSRs
Batch Creating Certificates
Generate an ASN.1 Dump of a Certificate
_Hidden
Quick Start Guide - Start EJBCA Container with Unauthenticated Network Access
Quick Start Guide - Issue Client Authentication Certificate using EJBCA
Get started with EJBCA Community container on AWS
Tutorial - Use an ephemeral CA and revoke ephemeral certificates
Quick Start Guide - PQC Lab Test Drive
Tutorial - Create a Post-Quantum PKI
Tutorial - Build a Post-Quantum Ready PKI with Chimera/Catalyst CAs
Tutorial - Create Post-Quantum Cryptography Chimera CA Chain
Tutorial – Issue a PQC Chimera End Entity Certificate with ML-KEM
Tutorial - Deploy EJBCA using a Helm chart
Tutorial - Deploy EJBCA Enterprise CA with Helm chart
Tutorial - Lift & Shift Your EJBCA Setup: Automate with ConfigDump
Tutorial - Automate EJBCA RA Deployment with Helm and ConfigDump
Tutorial - Issue Matter IoT-compliant certificates with EJBCA
Tutorial - Start out with EJBCA Docker container
Tutorial - Create your first Root CA using EJBCA
Tutorial - Create a PKI Hierarchy in EJBCA
Tutorial - Issue TLS server certificates with EJBCA
Tutorial - Issue TLS client certificates with EJBCA
Tutorial - Configure EJBCA to issue short-lived (ephemeral) certificates
Tutorial - Create roles in EJBCA
Tutorial - Deploy EJBCA container in MicroK8s
Tutorial - Clean up MicroK8s Cluster and Redeploy with Helm
Tutorial - Deploy Istio and cert-manager with Helm to Issue Mesh Certificates from EJBCA
Tutorial - Deploy Istio Service Mesh in a Multi-Cluster Kubernetes Environment Using EJBCA as an External PKI provider
Tutorial - Use EJBCA with HashiCorp Vault
Tutorial - Use EJBCA with cert-manager
Tutorial - Integrate EJBCA with SPIFFE SPIRE Server
Tutorial - Get started with device identities based on IEEE 802.1AR
Video Tutorial - Setting up a Free Trial Version of EJBCA on AWS
Video Tutorial - Creating an Ansible AWS Instance for EJBCA
Monitor EJBCA host using Monit
Configure EJBCA for NXP EdgeLock 2GO Service Platform
Tutorial - Install MicroK8s to run EJBCA
Tutorial - Deploy EJBCA container to issue certificates to an Istio service mesh
Securing the Software Supply Chain with Chainloop
Remote Signing of Attestations using Chainloop and SignServer
Local Signing of Attestations with Chainloop and EJBCA Ephemeral Certificates
Troubleshooting
Command Line Interface
Cryptography and Security
Installation and Deployment
Enrollment Questions
Performance/Timeouts
Publishing
Validation Authority
Troubleshoot Database Performance
PKI Management
_HSM Vendor-specific Information